What Is Gramm-Leach-Bliley Act?
The Gramm-Leach-Bliley Act (also called the Financial Services Modernization Act) is the federal framework for how financial institutions collect, share, and protect non-public personal information (NPI). GLBA applies broadly, not just to banks but to any business 'significantly engaged' in financial activities: mortgage lenders, credit reporting bureaus (alongside FCRA), insurers, securities firms, loan servicers, debt collectors, tax preparers, and real-estate settlement services. GLBA is built on three pillars: the Privacy Rule (transparency via annual notices), the Opt-Out Rule (consumer control over NPI sharing with non-affiliated third parties), and the Safeguards Rule (administrative, technical, and physical security programs). The 2023 Safeguards Rule amendments added a 30-day incident-reporting requirement.
At a glance
- Full name
- Gramm-Leach-Bliley Act
- Short code
- GLBA
- Enacted
- 1999
- Last major update
- Safeguards Rule 2023 amendments (incident reporting)
- Jurisdiction
- United States (federal)
- Private right of action
- No
- Primary enforcer
- FTC, CFPB, federal banking regulators (OCC, FDIC, NCUA, Federal Reserve), state insurance regulators
- Statutory citation
- 15 U.S.C. §§ 6801-6809
Scope, who GLBA covers
Protected data
Consumer rights & protections
Right to receive a privacy notice at the start of a customer relationship and annually (in some cases, only when material changes occur, post-FAST Act 2015)
Right to opt out of the sharing of NPI with non-affiliated third parties (with limited exceptions)
Right to reasonable security protecting your NPI (via the Safeguards Rule)
Right to receive notice of security incidents affecting your data (per 2023 Safeguards Rule amendments, 500+ consumer threshold)
Right to consumer protections against pretexting, obtaining financial info through false pretenses is criminal under GLBA
Notable features
GLBA's opt-out is one of only a handful of federal privacy opt-outs. The 2023 Safeguards Rule amendments introduced the first federal incident-reporting requirement for financial institutions (modeled on state breach-notification laws). GLBA famously exempts information shared with CRAs under FCRA, meaning a bank's data sharing with Experian/Equifax/TransUnion is governed by FCRA, not GLBA.
Enforcement & penalties
Enforcing agency: FTC, CFPB, federal banking regulators (OCC, FDIC, NCUA, Federal Reserve), state insurance regulators
Penalties: Civil penalties up to $100,000 per violation for institutions; $10,000 per violation for officers and directors. Criminal pretexting penalties include fines up to $500,000 and up to 5 years imprisonment. Safeguards Rule violations routinely produce FTC consent decrees with multi-year compliance monitoring.
Private right of action: GLBA does not grant a private right of action, enforcement is exclusive to the FTC, CFPB, and prudential regulators. Consumers harmed by a GLBA violation generally must rely on state common-law claims (breach of contract, negligence) or state privacy laws to sue directly.
Landmark enforcement cases
FTC v. Ascension Data & Analytics
2020The FTC settled with a mortgage analytics firm for failing to ensure that a service provider adequately secured personal information of tens of thousands of mortgage holders, an early enforcement of the Safeguards Rule's service-provider oversight obligations.
Official source →Relevance to data brokers
GLBA is the governing law when a data broker acquires financial NPI from banks, credit unions, mortgage brokers, or insurers. Brokers that aggregate financial data are often covered indirectly through GLBA's service-provider obligations, and financial institutions that share NPI must give consumers opt-out notices first. If your financial data reached a broker via a bank's third-party sharing program, GLBA opt-out at the source institution is the correct remediation path.
Exercise your rights
Remove your data from 500+ brokers for $7
OfflistMe drafts opt-out emails citing GLBA and other applicable laws. Citations included. You send from your own inbox. No account, no ID upload.
Request Removal NowFrequently Asked Questions
Does GLBA apply to fintechs and payment apps?
+
Yes, if they are 'significantly engaged' in financial activities, lending, money transmission, payment processing, or offering accounts that function like deposit accounts. PayPal, Cash App, Venmo, and Chime are generally considered GLBA financial institutions for their core financial services.
How do I opt out of GLBA sharing?
+
Each financial institution must provide an opt-out method in its annual privacy notice, typically a checkbox, toll-free number, or URL. The opt-out applies to sharing with non-affiliated third parties and must remain effective until revoked. Note: the opt-out does NOT cover sharing with affiliates (other companies under common ownership) or service providers performing the institution's own functions.
Does GLBA override state privacy laws?
+
No. GLBA has no express preemption of stronger state laws. A state like California (CCPA) can impose additional requirements on GLBA-covered institutions for the non-GLBA portions of their business (e.g., marketing data that is not NPI). Financial institutions must comply with both.
Who must comply with the GLBA Safeguards Rule? Does it apply to collection agencies?
+
The Safeguards Rule (16 CFR Part 314) applies to financial institutions under FTC jurisdiction, non-bank businesses significantly engaged in financial activities: mortgage lenders and brokers, payday lenders, finance companies, auto dealers that extend financing, check cashers, tax preparers, credit counselors, investment advisors not required to register with the SEC, and yes, collection agencies, because collecting on debts is a financial activity under section 4(k) of the Bank Holding Company Act. Covered businesses must designate a qualified individual to run the security program, perform a written risk assessment, encrypt customer data in transit and at rest, require multi-factor authentication, monitor and test systems, oversee service providers, and maintain an incident-response plan. Since May 2024, they must also notify the FTC within 30 days of a breach involving unencrypted information of 500 or more consumers. Institutions holding information on fewer than 5,000 consumers are exempt from some of the written-documentation requirements.
What section of GLBA requires the opt-out notice?
+
Section 502 of GLBA (codified at 15 U.S.C. § 6802) requires the opt-out notice. Specifically, § 502(b) prohibits a financial institution from sharing non-public personal information with non-affiliated third parties unless it has first given the consumer a clear and conspicuous notice and a reasonable opportunity to opt out. The related disclosure obligations sit in Section 503 (15 U.S.C. § 6803), which requires the initial and annual privacy notices that carry the opt-out. Both are implemented by Regulation P (12 C.F.R. Part 1016), administered by the CFPB.
Why are mortgage brokers regulated under the GLBA?
+
Under 15 U.S.C. § 6809 and Section 4(k) of the Bank Holding Company Act, any entity significantly engaged in financial activities—including mortgage lending, loan brokering, debt collection, loan servicing, and financial advisory services—is classified as a financial institution under GLBA and must provide privacy notices and Safeguards protection.
What is the difference between GLBA vs SOX (Sarbanes-Oxley)?
+
GLBA (Gramm-Leach-Bliley Act) governs consumer financial data privacy, opt-out rights, and technical safeguards for non-public personal information (NPI). SOX (Sarbanes-Oxley Act) governs corporate financial reporting, internal accounting controls, and executive accountability to prevent corporate fraud in publicly traded companies.
Official sources & citations
Other federal privacy laws
Federal privacy law is sectoral, each statute covers a specific data type or industry. Here are the other federal regimes to know alongside GLBA:
